The instant disclosure is directed to an attack/unwanted activity detecting firewall for use in protecting authentication-based network resources. The instant system is adapted for installation inline or in sniffer mode. In various embodiments, defined rules are applied to network traffic to determine whether certain types of attacks are occurring on the network resources. If one such attack is detected, the system provides for several potential responses, including for example disconnecting the attacking remote machine, requiring the user at that machine to re-authenticate, and/or requiring a second factor of authentication from the user at that machine. In some example embodiments, regardless of any activity required of a user at the remote machine suspected of malicious behavior, the disclosed system generates an alarm or other alert for presentation as appropriate, such as via a graphical user interface or a third-party system using an API.
Legal claims defining the scope of protection, as filed with the USPTO.
4. The system of claim 3, wherein affecting a future analysis of first portions of future received network traffic comprises altering a collection of algorithms configured to determine whether the first portion is indicative of an attack on the protected computer resource.
8. The system of claim 1, wherein the plurality of instructions further cause the at least one processor to operate with at least one network interface device to enforce the security policy.
9. The system of claim 1, wherein the plurality of instructions further cause the at least one processor to operate with at least one network interface device to receive the security policy from a third party resource.
14. The method of claim 13, wherein affecting a future analysis of first portions of future received network traffic comprises altering a collection of algorithms configured to determine whether the first portion is indicative of an attack on the protected computer resource.
19. The system of claim 1, wherein the security policy is updated based on at least one of external network details, past analyzed external network weaknesses, and past analyzed external network patterns of activity.
20. The method of claim 11, wherein the security policy is updated based on at least one of external network details, past analyzed external network weaknesses, and past analyzed external network patterns of activity.
Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.
December 5, 2018
November 15, 2022
Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.